在 Linux 内核中,已解决以下漏洞: ntfs:在 中为属性列表的预读(look-ahead)条目设置边界 当使用非零的 进行属性查找时, 会预读下一个 条目,以决定是否继续搜索。然而,该预读条目(尚未校验)仅通过 (仅证明前 0..6 字节在范围内)和 (其中 由攻击者控制且未按 8 字节对齐)来限制范围。随后,代码读取 (位于偏移 8 处的 )和 处的名称,这些字段可能位于 (即 分配的属性列表缓冲区的精确末尾,按磁盘上的 分配,无填充对齐)之外。因此,一个精心构造的磁盘上 ,若其最后一个条目位于 前几字节
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1e9ea7e04472d4e5e12e58c881eaacfb3e49b669< 44885c9b45eb4082fb7f558590d84bb254a08e94 |
affected |
1e9ea7e04472d4e5e12e58c881eaacfb3e49b669< 344b18f389f9934d59c7b0cf3d20541ea2e0da58 |
affected | ||
7.1 |
affected | ||
< 7.1 |
unaffected | ||
7.1.5≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80694 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80668 | 9.8 CRITICAL | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80634 | 9.8 CRITICAL | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80674 | 9.8 CRITICAL | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80630 | 9.8 CRITICAL | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin |
| CVE-2026-80617 | 9.8 CRITICAL | net: airoha: fix foe_check_time allocation size |
| CVE-2026-80612 | 9.8 CRITICAL | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80714 | 9.8 CRITICAL | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80609 | 9.8 CRITICAL | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80681 | 9.8 CRITICAL | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80600 | 9.8 CRITICAL | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80671 | 9.3 CRITICAL | perf sched: Fix register_pid() overflow, strcpy, and BUG_ON |
| CVE-2026-80684 | 9.3 CRITICAL | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80693 | 9.3 CRITICAL | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80670 | 9.1 CRITICAL | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80603 | 9.1 CRITICAL | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80683 | 8.8 HIGH | Bluetooth: SCO: give the socket its own sco_conn reference |
| CVE-2026-80692 | 8.8 HIGH | Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks |
| CVE-2026-80633 | 8.8 HIGH | iommufd: Take dma_resv lock before dma_buf_unpin() in release path |
| CVE-2026-80672 | 8.8 HIGH | ntfs: fix u16 truncation of restart-area length check |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet